TIP: You can type at any time to perform a new search.
Auth Api Key
auth_api_key · OCA/server-auth
Security findings
- Repository
- OCA/server-auth · module folder · Try on Runboat
- Module version
- 1.1.0
- Category
- Uncategorized
- Folder size
- 0.07 MB
- License
- LGPL-3
- Application
- No
- Auto-installable
- No
- Website
- https://github.com/OCA/server-auth
- Last tracking update
- 2026-10-04 00:16:48
- Authors
- ACSONE SA/NV, Odoo Community Association (OCA)
- Maintainers
- ACSONE SA/NV, Odoo Community Association (OCA)
- Committers
- Moises Lopez, Iván Todorovich, Maksym Yankin, Weblate, OCA-git-bot, oca-ci, arantxa-s73
- Odoo dependencies
- Python dependencies
- None
- System dependencies
- None
- Required by
- auth_api_key_group, base_rest_auth_api_key
- Description
Authenticate http requests from an API key. API keys are codes passed in (in the http header API-KEY) by programs calling an API in order to identify -in this case- the calling program's user. Take care while using this kind of mechanism since information into http headers are visible in clear. Thus, use it only to authenticate requests from known sources. For unknown sources, it is a good practice to filter out this header at proxy level. Odoo allows users to authenticate `XMLRPC/JSONRPC` calls using their API key instead of a password by native API keys (`res.users.apikey`). However, `auth_api_key` has some special features of its own such as: - API keys remain usable even when the user is inactive, if enabled via settings (e.g., for system users in a shopinvader case). - Supports dual authentication via Basic Auth and API_KEY in separate HTTP headers. - Admins can manage API keys for all users Given these advantages, particularly in use case like system user authentication, we have decided to keep the `auth_api_key` module
Code Analysis
Views touched (3)
| XML ID | Name | Model | Type | Status |
|---|---|---|---|---|
auth_api_key_form_view |
auth.api.key.form (in auth_api_key) | auth.api.key | form | New |
auth_api_key_tree_view |
auth.api.key.list (in auth_api_key) | auth.api.key | list | New |
res_config_settings_view_form |
res.config.settings.form.inherit | res.config.settings | form | Inherits base_setup.res_config_settings_view_form |
HTTP endpoints (0)
No HTTP endpoints found for this module.
Models touched (4)
New fields (4)
-
activeBooleancompute='_compute_active'default=Truereadonly=Falsestore=True -
keyChardefault=<expr>help='The API key. Enter a dummy value in this field if it is\n obtained from the server environment configuration.' -
nameCharrequired=True -
user_idMany2one → res.userscomodel_name='res.users'help='The user used to process the requests authenticated by\n the api key'required=Truestring='User'
-
create(self, vals_list)@api.model_create_multi -
generate_random_key(self, api_key_ids=None)Generate a key for records that do not have one yet. :param list api_key_ids: optional record IDs, mainly used by XML data function calls where the method is invoked on the model. :return: True when the operation completed. -
write(self, vals)
New fields (0)
No new fields.
Public methods (0)No public methods.
New fields (1)
-
archived_user_disable_auth_api_keyBooleanhelp='If checked, when a user is archived/unactivated the same change is propagated to his related api key. It is not retroactive (nothing is done when enabling/disabling this option).'string='Disable API key for archived user'
No public methods.
New fields (1)
-
archived_user_disable_auth_api_keyBooleanreadonly=Falserelated='company_id.archived_user_disable_auth_api_key'
No public methods.
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…